Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management. A high‑privileged attacker with network access over HTTP can exploit it to compromise the application and ultimately gain full control of the system. The CVSS vector shows that a successful exploit would give an attacker the ability to read, modify, or delete all data and to disrupt the availability of the service, resulting in loss of confidentiality, integrity, and availability for all data handled by the application.
Affected Systems
The affected product is Oracle Hyperion Financial Management from Oracle Corporation. The only impacted version reported is 11.2.26.0.000; no other versions are included.
Risk and Exploitability
The CVSS Base Score of 7.2 indicates medium‑high severity, with the EPSS score of less than 1 % showing a low but non‑zero probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires network access over HTTP and high privilege credentials; it needs no user interaction. Consequently, the threat is most acute for insiders or attackers who already bypassed other controls, and the low attack complexity makes the vulnerability particularly dangerous once access is obtained.
OpenCVE Enrichment